A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resource used to change the roles and permissions of a user. This could allow an attacker to change the permissions of any user and gain the privileges of an administrative user.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/html/ssa-484086.html |